BUILD IN PROGRESS · SEPTEMBER 2026

A sovereign operating system for AI work.

ADYX builds Charles — a control plane that sits between human intent and a fleet of models, agents, apps, machines, and real-world systems. Models are replaceable cognition. Charles owns the memory, the policy, the identity, the orchestration, and the evidence.

1 mind
DURABLE, PRIVATE, OWNED
Many limbs
PHONE, DESKTOP, TERMINAL, VOICE
Any model
REPLACEABLE COGNITION
0 on trust
EVERY ACTION VERIFIED FIRST
01 — THESIS

Own the mind. Buy the commodity.

Most AI products begin with a model and add tools around it. Charles is built in the opposite direction. It begins with a durable, private representation of a person's world: what they have decided, what they are building, what they have delegated, what the system observed, and what it is allowed to do.

Compute and model weights are a market. Identity, memory, authority, and evidence are not — they compound, and they cannot be bought off the shelf. That asymmetry is the entire product strategy.

MEMORY

Immutable raw capture, structured records on top, provenance on every recall.

POLICY

Authority and sensitivity classified before anything runs. Ambiguity fails closed.

IDENTITY

Charles acts as Charles, on stated behalf — never as a silent impersonation.

EVIDENCE

A receipt proves resulting state and records what remains unobservable.

FIG. 01THE OPERATING LOOP
CAPTURE
text · voice · events
DURABLE MIND
owned memory
POLICY
who may act
AGENT TEAM
lead · specialists
VERIFIED ACTION
proof, not claims
RECEIPT
canonical evidence

EVERY RESULT BECOMES FUTURE CONTEXT · EVERY CORRECTION BECOMES LAW

02 — ARCHITECTURE

One presence, many limbs

Every surface — phone, Mac, terminal, voice — is a disposable limb around one control plane. No limb owns a capability. Charles decides which model tier serves which work, and every action flows back as evidence.

FIG. 02SYSTEM MAP
PHONE
capture on the go
MAC COCKPIT
command center
TERMINAL
direct sessions
VOICE
speak + listen
OBSERVERS
comms · house
CHARLES — THE CONTROL PLANE
MEMORY · POLICY · IDENTITY · ORCHESTRATION · RECEIPTS
ROUTES RECEIPTS
FRONTIER MODELS
high-authority judgment
MID-TIER MODELS
routine support work
FENCED VENDOR
sensitive content only
REAL-WORLD SYSTEMS
apps · comms · machines

MODELS AND COMPUTE ARE REPLACEABLE · THE CONTROL PLANE IS NOT

ROUTING

The tier is set by the work, not by a default. High-authority judgment gets frontier capability; routine support runs cheaper.

FENCING

Sensitive content is confined to an approved vendor regardless of price. Privacy is a constraint, not a preference.

MEASUREMENT

Cost, provenance, privacy, and correctness are read off a production usage ledger — not estimated.

03 — GOVERNANCE

No request executes on trust

Every unit of work is classified by authority and sensitivity before anything runs, and every result must survive an adversarial pipeline before it becomes a receipt. No single agent can author, approve, and verify its own work.

FIG. 03CLASSIFICATION GATE
INCOMING WORK
task · message · action
CLASSIFY
authority + sensitivity
MACHINE-RESOLVABLEhousekeeping — machines may decide
HUMAN KEY REQUIREDdoctrine · spend · risk · sensitive
AMBIGUOUSfails closed — nothing runs

SMALL DECISION SURFACE: QUESTION · OPTIONS · RECOMMENDATION · EVIDENCE

FIG. 04ADVERSARIAL PIPELINE
LEAD
owns integration
SPECIALISTS
bounded, isolated lanes
SKEPTIC
attacks the leading answer
VERIFIER
fresh eyes, immutable version
RECEIPT
proven state, not claims

APPROVED WORK ENTERS AN ADVERSARIAL PIPELINE BEFORE IT COUNTS

Identity is not impersonation

Outbound communication uses Charles's own identity, names that it acts on its principal's behalf, passes recipient and content gates, and writes an audit record. Money-moving requests are refused structurally, not by convention.

A receipt is not a log line

"The command ran" is not proof. Charles attempts to prove the resulting state, records what remains unobservable, and files both as canonical evidence that later work can rely on.

04 — STATUS

What is real, and what is staged

Charles is not a finished commercial product. Some limbs are live, some are working prototypes, and deeper orchestration remains staged. The durable architecture and the operating laws are the part built most deliberately.

LIVE TODAY

  1. Local-first capture and memory pipeline for text, voice, and structured events, with canonical receipts.
  2. Search and recall across decisions, doctrine, journals, projects, and prior work — provenance attached.
  3. Multi-agent execution with independent skeptics attempting to disprove the result.
  4. Risk-aware model routing by authority and sensitivity.
  5. Working phone, Mac, terminal, voice, and ambient limbs on one system.
  6. Governed communications with recipient controls and audit trails.
  7. Private cognition on owned hardware, working alongside frontier models.
  8. A multi-session command center: one lead, many working lanes, each handoff made from verified state.

DELIBERATELY UNFINISHED

Automatic cross-provider continuation is an active design and build area, not a deployed claim. A safe handoff must start a fresh successor from verified durable task state, fence stale workers, and produce an acceptance receipt. It cannot pretend one vendor's live conversation moved seamlessly into another.

A fully local core is in the same category: partly live, not claimed. The reconstitution test is the bar — any laptop, app, or model is disposable, and the mind is rebuildable from durable state.

STATED PLAINLY BECAUSE THE ALTERNATIVE IS A DEMO, NOT A SYSTEM

When models are interchangeable, what do you actually own?

My answer is the mind, the policy, and the proof. I'm sharing this with people building in the same direction — not as a product claim or a pitch, but as a technical conversation I'd like to have.

WHO THIS IS FOR

  • Builders working on agent memory, policy, or provenance.
  • Operators who need AI actions to be auditable, not plausible.
  • Investors interested in the layer above the model layer.
NICK MURPHY
FOUNDER, ADYX.AI
SEPTEMBER 2026